Are you interested in a write-up about an XSS bug on a public program on @Hacker0x01 . Cool WAF bypass using parameter pollution combined with an access control issue to result in account takeover.

#bugbounty #hackerone